CVE-2019-12773
- EPSS 0.23%
- Veröffentlicht 14.07.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:32
An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scrip...
CVE-2019-12783
- EPSS 0.2%
- Veröffentlicht 14.07.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:34
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "crowdsource...
CVE-2019-12784
- EPSS 0.23%
- Veröffentlicht 14.07.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:34
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on th...